The significant recent growth in digitization has been accompanied by a rapid increase in cyber attacks affecting all sectors. Thus, it is fundamental to make a correct assessment of the risk to suffer a cyber attack and of the resulting damage. Quantitative loss data are rarely available, while it is possible to obtain a qualitative evaluation on an ordinal scale of the gravity of an attack from experts of the sector. In this paper, we discuss how network models can be useful instruments for the evaluation of the risk associated to a cyber attack. In particular, we consider Bayesian Networks, Random Forests and Social Networks to study different aspects of the examined problem. Along with the description of the methodology, we examine a real set of data regarding serious cyber attacks occurred worldwide before and during the pandemic due to Covid-19. In the analysis, we also investigate how the Covid-19 period had an impact on the cyber risk landscape in terms of frequency and gravity of the observed attacks.

Network models for cyber attacks evaluation / S. Facchinetti, S. Osmetti, C. Tarantola. - In: SOCIO-ECONOMIC PLANNING SCIENCES. - ISSN 0038-0121. - 87:B(2023 Jun), pp. 101584.1-101584.13. [10.1016/j.seps.2023.101584]

Network models for cyber attacks evaluation

C. Tarantola
Ultimo
2023

Abstract

The significant recent growth in digitization has been accompanied by a rapid increase in cyber attacks affecting all sectors. Thus, it is fundamental to make a correct assessment of the risk to suffer a cyber attack and of the resulting damage. Quantitative loss data are rarely available, while it is possible to obtain a qualitative evaluation on an ordinal scale of the gravity of an attack from experts of the sector. In this paper, we discuss how network models can be useful instruments for the evaluation of the risk associated to a cyber attack. In particular, we consider Bayesian Networks, Random Forests and Social Networks to study different aspects of the examined problem. Along with the description of the methodology, we examine a real set of data regarding serious cyber attacks occurred worldwide before and during the pandemic due to Covid-19. In the analysis, we also investigate how the Covid-19 period had an impact on the cyber risk landscape in terms of frequency and gravity of the observed attacks.
Bayesian Network; Cyber risk; DAG; Random Forest; Social Network;
Settore SECS-S/01 - Statistica
Settore STAT-01/A - Statistica
giu-2023
https://www.sciencedirect.com/science/article/pii/S0038012123000848?via=ihub
Article (author)
File in questo prodotto:
File Dimensione Formato  
Facchinetti_Osmetti_Tarantola_2023_netwrok.pdf

accesso aperto

Tipologia: Publisher's version/PDF
Dimensione 4.72 MB
Formato Adobe PDF
4.72 MB Adobe PDF Visualizza/Apri
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/2434/1073908
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 4
  • ???jsp.display-item.citation.isi??? 2
social impact